Lurk banking trojan is distributed via compromised Ammyy Admin website

Lurk banking trojan is distributed via compromised Ammyy Admin website

Ammyy Admin is an analog of TeamViewer solution, which allows remote administration of clients’ PCs. It is used mostly in Russia by corporate and home users.

Researchers from Kaspersky Lab discovered new distribution technique of banking trojan Lurk. According to report, hackers were able to compromise website of Russian Ammyy Admin remote administration tool and deliver malware along with legit application to victims’ computers.

Ammyy Admin is delivered as NSIS archive, which contains two binaries inside:

aa_v3.exe – legit digitally signed installer of Ammyy Admin

ammyysvc.exe – trojan, detected by Kaspersky Lab as Trojan-Spy.Win32.Lurk.

This is the second time when Ammyy Admin website gets hacked and distributes malware. The previous incident occurred in November, 2015. Hackers were able to compromise the website and slightly change PHP code, responsible for Ammyy Admin delivery. As a result, the victim downloaded legit application along with malware dropper.

At the moment of this writing, the downloaded binary AA_v3.exe is digitally signed and does not seem to contain malicious code.


Back to the list

Latest Posts

US agencies warn of rising cyber threats from Iran-linked hackers

US agencies warn of rising cyber threats from Iran-linked hackers

Recent months have seen a notable uptick in activity from Iranian-linked hacktivists and government-affiliated threat groups.
1 July 2025
Google rolls out urgent Chrome security patch for active zero-day

Google rolls out urgent Chrome security patch for active zero-day

The flaw, tracked as CVE-2025-6554, is described as a type confusion bug in Chrome's V8 JavaScript and WebAssembly engine.
1 July 2025
Canada bans Chinese surveillance firm Hikvision over national security concerns

Canada bans Chinese surveillance firm Hikvision over national security concerns

From now on, all federal departments, agencies, and Crown corporations are prohibited from purchasing Hikvision products.
1 July 2025